Page MenuHomeVyOS Platform
Feed All Stories

Apr 10 2024

HollyGurza added a comment to T6106: Improve the commit error message for the case when route-reflector-client option is defined in a peer-group.

i think yes, now we will show frr logs for unhandled exceptions and normal short messages for others e.g. route-reflector-client only supported for iBGP peers

Apr 10 2024, 3:45 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
Thunderstorm claimed T6220: add IPv6 support for TACACS.
Apr 10 2024, 2:25 AM · VyOS 1.5 Circinus
Thunderstorm created T6220: add IPv6 support for TACACS.
Apr 10 2024, 2:25 AM · VyOS 1.5 Circinus
Giggum added a comment to T5694: NTP should always be allowed from localhost and bindaddress/binddevice can only exist once.

I gave it a go due to similarities between this and https://vyos.dev/T6123.

Apr 10 2024, 2:07 AM · VyOS 1.5 Circinus

Apr 9 2024

tgnthump added a comment to T6219: sysctl support for containers.

Started on a PR: https://github.com/vyos/vyos-1x/pull/3288

Apr 9 2024, 7:45 PM · VyOS 1.4 Sagitta (1.4.0-GA)
Viacheslav triaged T6218: Container network interface in VRF fails to generate IPv6 link-local address as Normal priority.
Apr 9 2024, 7:35 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
tgnthump added a comment to T6219: sysctl support for containers.

My specific use case is a container that requires --sysctl=net.ipv4.conf.all.forwarding=1

Apr 9 2024, 6:41 PM · VyOS 1.4 Sagitta (1.4.0-GA)
tgnthump created T6219: sysctl support for containers.
Apr 9 2024, 6:30 PM · VyOS 1.4 Sagitta (1.4.0-GA)
jvoss updated the task description for T6218: Container network interface in VRF fails to generate IPv6 link-local address.
Apr 9 2024, 6:28 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
jvoss claimed T6218: Container network interface in VRF fails to generate IPv6 link-local address.
Apr 9 2024, 6:19 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
jvoss created T6218: Container network interface in VRF fails to generate IPv6 link-local address.
Apr 9 2024, 6:19 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav closed T3409: Add back TCP-MSS Clamp to PMTU as Resolved.

Mark it as resolved, reopen the task if required.

Apr 9 2024, 4:21 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T6106: Improve the commit error message for the case when route-reflector-client option is defined in a peer-group.

Was it fixed?

Apr 9 2024, 4:12 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav changed the status of T6106: Improve the commit error message for the case when route-reflector-client option is defined in a peer-group from In progress to Needs testing.
Apr 9 2024, 4:12 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav added a comment to T6124: Docker equuleus build image doesn't build due to fpm.

@MattK Could you re-check and close it?

Apr 9 2024, 4:08 PM · VyOS 1.3 Equuleus (1.3.7)
Viacheslav changed the status of T6132: Conntrack-sync Internal Cache Growing Uncontrollably from Open to Needs reporter action.
Apr 9 2024, 4:06 PM · Restricted Project, VyOS 1.5 Circinus
Viacheslav changed the status of T6212: Firewall offload counters show always zero from Open to Needs testing.
Apr 9 2024, 4:06 PM · VyOS 1.5 Circinus
Viacheslav added a comment to T2801: conntrack-tools flooding logs.

@tjh Any updates?
By the way there is a new option

vyos@r4# set service conntrack-sync disable-syslog 
[edit]
vyos@r4#
Apr 9 2024, 4:04 PM · VyOS 1.4 Sagitta (1.4.0-epa1), VyOS 1.3 Equuleus (1.3.7)
Viacheslav added a comment to T5745: conntrack-sync: Multiprimary setups for HA/VRRP.

https://conntrack-tools.netfilter.org/manual.html#sync-aa

conntrackd allows you to deploy an symmetric Active-Active setup based on a static approach. For example, assume that you have two virtual IPs, vIP1 and vIP2, and two firewall replicas, FW1 and FW2. You can give the virtual vIP1 to the firewall FW1 and the vIP2 to the FW2.
Apr 9 2024, 3:58 PM · VyOS 1.5 Circinus, vyatta-vrrp, vyatta-conntrack-sync
Viacheslav added a project to T6217: Set the log id of the VRRP contrack-sync script to vyos-vrrp-conntracksync: Restricted Project.
Apr 9 2024, 2:56 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav added a comment to T6132: Conntrack-sync Internal Cache Growing Uncontrollably.

@trae32566 Can you provide the next output?

sudo conntrackd -C /run/conntrackd/conntrackd.conf -s  && echo "conntrack_count: " && sudo conntrack -C
sudo conntrackd -C /run/conntrackd/conntrackd.conf -s network
sudo conntrackd -C /run/conntrackd/conntrackd.conf -s cache
sudo conntrackd -C /run/conntrackd/conntrackd.conf -s runtime
sudo conntrackd -C /run/conntrackd/conntrackd.conf -s link
sudo conntrackd -C /run/conntrackd/conntrackd.conf -s queue
Apr 9 2024, 1:05 PM · Restricted Project, VyOS 1.5 Circinus
Viacheslav triaged T6217: Set the log id of the VRRP contrack-sync script to vyos-vrrp-conntracksync as Low priority.
Apr 9 2024, 12:21 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav created T6217: Set the log id of the VRRP contrack-sync script to vyos-vrrp-conntracksync.
Apr 9 2024, 12:20 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
n.fort added a subtask for T5938: Migration fail root task for 1.4-rc: T6216: Firewall group names that contain the '+' character break the config.
Apr 9 2024, 12:20 PM · Restricted Project, VyOS 1.4 Sagitta (1.4.1)
n.fort added a parent task for T6216: Firewall group names that contain the '+' character break the config: T5938: Migration fail root task for 1.4-rc.
Apr 9 2024, 12:20 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
HollyGurza added a comment to T6206: L2tp smoketest fails if vyos-configd is running.

https://github.com/vyos/vyatta-cfg/pull/77

Apr 9 2024, 12:11 PM · VyOS 1.4 Sagitta (1.4.0-epa3), VyOS 1.5 Circinus
n.fort changed the status of T6216: Firewall group names that contain the '+' character break the config from Open to Confirmed.
Apr 9 2024, 12:11 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
n.fort created T6216: Firewall group names that contain the '+' character break the config.
Apr 9 2024, 12:11 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
n.fort added a comment to T6213: Validations in firewall groups mistakenly reject correct configurations.

PR: https://github.com/vyos/vyos-1x/pull/3281

Apr 9 2024, 11:13 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
n.fort added a comment to T6214: Error when using some constraints.

PR: https://github.com/vyos/vyos-1x/pull/3281

Apr 9 2024, 11:13 AM · VyOS 1.4 Sagitta (1.4.0-epa2)
a.hajiyev added a comment to T6215: Replace confusing error messages with clear ones when delete rule form firewall policy.

https://github.com/vyos/vyatta-cfg-firewall/pull/37

Apr 9 2024, 10:56 AM · VyOS 1.3 Equuleus (1.3.8)
a.hajiyev created T6215: Replace confusing error messages with clear ones when delete rule form firewall policy.
Apr 9 2024, 10:51 AM · VyOS 1.3 Equuleus (1.3.8)
Viacheslav moved T6121: Extend service config-sync for sections vpn, policy, vrf from Need Triage to Finished on the VyOS 1.4 Sagitta (1.4.0-epa3) board.
Apr 9 2024, 10:32 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav edited projects for T6121: Extend service config-sync for sections vpn, policy, vrf, added: VyOS 1.4 Sagitta (1.4.0-epa3); removed VyOS 1.4 Sagitta (1.4.0-epa2).
Apr 9 2024, 10:32 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav moved T6121: Extend service config-sync for sections vpn, policy, vrf from Open to Finished on the VyOS 1.5 Circinus board.
Apr 9 2024, 10:32 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav closed T6121: Extend service config-sync for sections vpn, policy, vrf as Resolved.
Apr 9 2024, 10:32 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav changed the status of T5858: Improve the formatting of conntrack statistics output from Open to In progress.

PR https://github.com/vyos/vyos-1x/pull/3280

vyos@r15-left:~$ show conntrack statistics 
CPU    Found    Invalid    Insert    Insert fail    Drop    Early drop    Errors    Search restart
-----  -------  ---------  --------  -------------  ------  ------------  --------  ----------------  --  --
0      0        280        0         1              1       0             1         0                 2   0
1      0        73         0         0              0       0             126       0                 1   0
vyos@r15-left:~$
Apr 9 2024, 10:30 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
n.fort renamed T6214: Error when using some constraints from Error when using some contraints to Error when using some constraints.
Apr 9 2024, 9:45 AM · VyOS 1.4 Sagitta (1.4.0-epa2)
n.fort created T6214: Error when using some constraints.
Apr 9 2024, 9:44 AM · VyOS 1.4 Sagitta (1.4.0-epa2)
Giggum updated the task description for T6123: Limit NTP allow-client config to internal addresses by default.
Apr 9 2024, 12:36 AM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
Giggum updated the task description for T6123: Limit NTP allow-client config to internal addresses by default.
Apr 9 2024, 12:18 AM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus

Apr 8 2024

Giggum added a comment to T6099: Suppress unsupported interfaces from appearing in messages log by Telegraf .

@Giggum Can you check it in 1.5?

Yeah sure thing I can do that. Will I be able to roll back from the latest 1.5 to the version of 1.4 rolling I’m on after testing is complete or will the config mess up?

Apr 8 2024, 11:17 PM · VyOS 1.5 Circinus
c-po edited projects for T6173: Build Causes Errors When "--version" Contains Slashes ("/"), added: VyOS 1.4 Sagitta (1.4.0-epa3); removed VyOS 1.4 Sagitta (1.4.0-epa2).
Apr 8 2024, 6:46 PM · VyOS 1.4 Sagitta (1.4.0-epa3), VyOS 1.5 Circinus
c-po added a comment to T6173: Build Causes Errors When "--version" Contains Slashes ("/").

https://github.com/vyos/vyos-build/pull/553

Apr 8 2024, 6:45 PM · VyOS 1.4 Sagitta (1.4.0-epa3), VyOS 1.5 Circinus
a.apostoliuk claimed T3770: BGP neighbor not generating the correct frr configuration when moved to peer-group.
Apr 8 2024, 2:30 PM · VyOS 1.3 Equuleus (1.3.7)
n.fort moved T6068: Support active-active and active-passive high availability modes in DHCP server from Open to Finished on the VyOS 1.5 Circinus board.
Apr 8 2024, 12:04 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
n.fort moved T6068: Support active-active and active-passive high availability modes in DHCP server from Open to Finished on the VyOS 1.4 Sagitta board.
Apr 8 2024, 12:03 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
n.fort closed T6068: Support active-active and active-passive high availability modes in DHCP server as Resolved.
Apr 8 2024, 12:03 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav changed the status of T3437: BGP Confederation Addition Causes Error from Needs testing to Confirmed.
Apr 8 2024, 11:36 AM · VyOS 1.3 Equuleus (1.3.7)
n.fort changed the status of T6213: Validations in firewall groups mistakenly reject correct configurations from Open to In progress.
Apr 8 2024, 11:12 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
n.fort created T6213: Validations in firewall groups mistakenly reject correct configurations.
Apr 8 2024, 11:11 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
a.apostoliuk added a comment to T3437: BGP Confederation Addition Causes Error.

Rechecked - The issue exists.

Apr 8 2024, 11:11 AM · VyOS 1.3 Equuleus (1.3.7)
a.apostoliuk changed the status of T6196: route-map and summary-only do not work in BGP aggregation at the same time from Unknown Status to Resolved.
Apr 8 2024, 11:05 AM · VyOS 1.3 Equuleus (1.3.7), VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav added a comment to T6212: Firewall offload counters show always zero.

After deleting and adding the firewall, it looks good
So, for some reason, the rule 10 and default action accept were applied 2 times to the firewall

	chain VYOS_FORWARD_filter {
		type filter hook forward priority filter; policy accept;
		counter packets 928376 bytes 1800341472 flow add @VYOS_FLOWTABLE_FLOWTABLE comment "ipv4-FWD-filter-10"
		counter packets 928376 bytes 1800341472 accept comment "FWD-filter default-action accept"
		counter packets 0 bytes 0 flow add @VYOS_FLOWTABLE_FLOWTABLE comment "ipv4-FWD-filter-10"
		ct state { established, related } counter packets 0 bytes 0 flow add @VYOS_FLOWTABLE_FLOWTABLE comment "ipv4-FWD-filter-20"
		counter packets 0 bytes 0 accept comment "FWD-filter default-action accept"
	}
Apr 8 2024, 11:04 AM · VyOS 1.5 Circinus
Viacheslav triaged T6212: Firewall offload counters show always zero as Normal priority.
Apr 8 2024, 10:55 AM · VyOS 1.5 Circinus
Viacheslav created T6212: Firewall offload counters show always zero.
Apr 8 2024, 10:52 AM · VyOS 1.5 Circinus
a.apostoliuk moved T6197: Validation error in the IPoE server interface client-subnet option from Open to Finished on the VyOS 1.5 Circinus board.
Apr 8 2024, 9:00 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
a.apostoliuk closed T6197: Validation error in the IPoE server interface client-subnet option as Resolved.
Apr 8 2024, 9:00 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
a.apostoliuk changed the status of T6197: Validation error in the IPoE server interface client-subnet option from In progress to Needs testing.
Apr 8 2024, 8:58 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
HollyGurza added a comment to T6206: L2tp smoketest fails if vyos-configd is running.

probably related task T5660

Apr 8 2024, 8:21 AM · VyOS 1.4 Sagitta (1.4.0-epa3), VyOS 1.5 Circinus
jestabro added a comment to T6207: image-tools: restore ability to copy config.boot.default on image install.

PRs:
https://github.com/vyos/vyos-1x/pull/3278
https://github.com/vyos/vyos-build/pull/551

Apr 8 2024, 4:10 AM · VyOS 1.4 Sagitta (1.4.0-epa3)

Apr 7 2024

Viacheslav added a project to T5169: Add CGNAT Carrier-Grade NAT based on nftables: VyOS 1.5 Circinus.
Apr 7 2024, 8:27 PM · VyOS Rolling, VyOS 1.5 Circinus
sarthurdev changed the status of T6163: kea-dhcp4-server crashes due to incorrect lease file permissions after 1.5-rolling-202403120022 -> 1.5-rolling-202403230018 upgrade from Confirmed to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/3277

Apr 7 2024, 8:14 PM · VyOS 1.5 Circinus
c-po updated the task description for T5475: Analyse if forked live-boot package can be dropped.
Apr 7 2024, 7:02 PM · VyOS 1.5 Circinus
c-po closed T5862: Default MTU is not acceptable in some environments as Resolved.
Apr 7 2024, 6:59 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
c-po moved T5862: Default MTU is not acceptable in some environments from Need Triage to Finished on the VyOS 1.4 Sagitta (1.4.0-epa3) board.
Apr 7 2024, 6:59 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
c-po closed T6205: ipoe: error in migration script logic while renaming mac-address to mac, a subtask of T5938: Migration fail root task for 1.4-rc, as Resolved.
Apr 7 2024, 6:59 PM · Restricted Project, VyOS 1.4 Sagitta (1.4.1)
c-po closed T6205: ipoe: error in migration script logic while renaming mac-address to mac as Resolved.
Apr 7 2024, 6:59 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
c-po moved T6205: ipoe: error in migration script logic while renaming mac-address to mac from Open to Finished on the VyOS 1.5 Circinus board.
Apr 7 2024, 6:59 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
c-po moved T6205: ipoe: error in migration script logic while renaming mac-address to mac from Need Triage to Finished on the VyOS 1.4 Sagitta (1.4.0) board.
Apr 7 2024, 6:58 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
c-po closed T6208: container: rename "cap-add" CLI node to "capability" as Resolved.
Apr 7 2024, 6:58 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
c-po moved T6208: container: rename "cap-add" CLI node to "capability" from Need Triage to Finished on the VyOS 1.4 Sagitta (1.4.0-epa3) board.
Apr 7 2024, 6:58 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
sarthurdev merged T6137: dhcp files and directory permission not correct after image uprgading into T6163: kea-dhcp4-server crashes due to incorrect lease file permissions after 1.5-rolling-202403120022 -> 1.5-rolling-202403230018 upgrade.
Apr 7 2024, 6:17 PM · VyOS 1.5 Circinus
sarthurdev merged task T6137: dhcp files and directory permission not correct after image uprgading into T6163: kea-dhcp4-server crashes due to incorrect lease file permissions after 1.5-rolling-202403120022 -> 1.5-rolling-202403230018 upgrade.
Apr 7 2024, 6:17 PM · VyOS 1.5 Circinus
sarthurdev changed the status of T6163: kea-dhcp4-server crashes due to incorrect lease file permissions after 1.5-rolling-202403120022 -> 1.5-rolling-202403230018 upgrade from Open to Confirmed.
Apr 7 2024, 6:11 PM · VyOS 1.5 Circinus
Viacheslav changed the status of T1641: VRRP conntrack-sync dropping packets passing through the router from Open to Needs reporter action.

@Daya @trae32566 Any updates?

Apr 7 2024, 5:20 PM · Restricted Project, VyOS 1.4 Sagitta (1.4.1)
Viacheslav placed T3159: L2TP MTU mismatch between client and server up for grabs.
Apr 7 2024, 5:11 PM · Restricted Project, VyOS 1.3 Equuleus (1.3.9), VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
Viacheslav added a comment to T5966: Adjust dynamic dns configuration address subpath to be more intuitive and other op-mode adjustments.

@indrajitr Can we close it?

Apr 7 2024, 5:06 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav added a comment to T5959: Streamline dns forwarding service.

@indrajitr Can we close it?

Apr 7 2024, 5:05 PM · VyOS 1.4 Sagitta (1.4.0-epa2)
Viacheslav changed the status of T4588: BGP Peer Group Scaling issues from Open to Needs reporter action.
Apr 7 2024, 5:03 PM · VyOS 1.4 Sagitta (1.4.1)
Viacheslav closed T6039: cloud-init DNS search-domain causes configuration migration/validation error, a subtask of T5907: cloud-init root task for 1.5 and 1.4 , as Resolved.
Apr 7 2024, 4:54 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta (1.4.1)
Viacheslav closed T6039: cloud-init DNS search-domain causes configuration migration/validation error as Resolved.
Apr 7 2024, 4:54 PM · VyOS 1.4 Sagitta
Viacheslav added a subtask for T5907: cloud-init root task for 1.5 and 1.4 : T6112: Cloud Init Ordering Incorrect.
Apr 7 2024, 4:45 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta (1.4.1)
Viacheslav added a parent task for T6112: Cloud Init Ordering Incorrect: T5907: cloud-init root task for 1.5 and 1.4 .
Apr 7 2024, 4:45 PM · Restricted Project, VyOS 1.4 Sagitta (1.4.1)
Viacheslav triaged T6208: container: rename "cap-add" CLI node to "capability" as Normal priority.
Apr 7 2024, 4:37 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav added a comment to T6099: Suppress unsupported interfaces from appearing in messages log by Telegraf .

@Giggum Can you check it on 1.5?

Apr 7 2024, 3:56 PM · VyOS 1.5 Circinus
Viacheslav added a comment to T5810: Add support for RPKI source ip.

It is easy to add
In FRR it looks like:

r4(config-rpki)# rpki cache 192.0.2.1 8888 
  SSH_UNAME   SSH user name
  preference  Preference of the cache server
  source      Configure source IP address of RPKI connection
Apr 7 2024, 3:22 PM · Restricted Project, VyOS 1.5 Circinus
Viacheslav closed T1244: Add support for StartupResync in conntrack-sync as Resolved.
Apr 7 2024, 3:15 PM · VyOS 1.4 Sagitta (1.4.0-epa3), VyOS 1.3 Equuleus (1.3.7)
Viacheslav triaged T6209: Improve Configuration Load/Commit Speed by moving away from deep-tree flat-file backend as Normal priority.
Apr 7 2024, 3:10 PM · VyOS 1.5 Circinus
Viacheslav added a comment to T5169: Add CGNAT Carrier-Grade NAT based on nftables.

PoC PR https://github.com/vyos/vyos-1x/pull/3274

set nat cgnat pool external ext1 external-port-range '1024-65535'
set nat cgnat pool external ext1 per-user-limit port '1000'
set nat cgnat pool external ext1 range 192.0.2.222/32
set nat cgnat pool internal int1 range '100.64.0.0/28'
set nat cgnat rule 10 source pool 'int1'
set nat cgnat rule 10 translation pool 'ext1'
Apr 7 2024, 2:36 PM · VyOS Rolling, VyOS 1.5 Circinus
daknob added a comment to T5810: Add support for RPKI source ip.

For me personally this change makes sense: a router has multiple interfaces, the Source IP is selected in different ways, and especially for RPKI servers outside the network (public ones), this could even break connectivity. Vendors like Juniper had this issue and eventually added the option, which means probably VyOS will benefit too, especially since "it's just setting a value in FRR's config"™ (famous last words ;).

Apr 7 2024, 1:05 PM · Restricted Project, VyOS 1.5 Circinus
Loremo added a comment to T5810: Add support for RPKI source ip.

Yes and no. Even before I created this ticket, I tried a small test locally. Unfortunately, I was not able to get the tests to run (even without my changes).

Apr 7 2024, 12:45 PM · Restricted Project, VyOS 1.5 Circinus
daknob added a comment to T5810: Add support for RPKI source ip.

@Loremo I think this contribution would be valuable. Have you made any progress with your PR?

Apr 7 2024, 11:39 AM · Restricted Project, VyOS 1.5 Circinus
evgbondarenko empowered vadmin as an administrator.
Apr 7 2024, 9:02 AM
dmbaturin reopened T6211: kea DHCP server not vrf aware as "Open".
Apr 7 2024, 8:17 AM · Restricted Project, VyOS 1.5 Circinus
dmbaturin closed T6211: kea DHCP server not vrf aware as Resolved.
Apr 7 2024, 6:08 AM · Restricted Project, VyOS 1.5 Circinus
dmbaturin closed T6188: Add firewall rule description to the output of "show firewall" commands as Resolved.
Apr 7 2024, 6:08 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
GurliGebis added a comment to T5873: ipsec remote access VPN: support VTI interfaces.

Great 😃

Apr 7 2024, 5:49 AM · VyOS Rolling, VyOS 1.5 Circinus
lucasec added a comment to T5873: ipsec remote access VPN: support VTI interfaces.

Hi -- this works. The VTI interface is just another interface so you can add it to a firewall zone just as you would an Ethernet interface. This can be done with existing site-to-site ipsec VTIs today. I also do it with OpenVPN interfaces for remote access on some of my installations.

Apr 7 2024, 1:57 AM · VyOS Rolling, VyOS 1.5 Circinus
Fr0stedD0nut added a comment to T5432: Add grub-settings to system section in VyOS config-mode.

This would be really useful. As per: https://forum.vyos.io/t/other-than-console-how-to-pass-grub-parameter-pcie-aspm-off/14203

Apr 7 2024, 12:27 AM · VyOS 1.5 Circinus